Agent tool catalog
Nerve exposes the tool names below. The contracts and manifest own the exact catalog; availability also depends on mode, permission, runtime discovery, module settings, and user toggles.
Files and execution
Section titled “Files and execution”- Inspection:
read,grep,find,ls - Editing:
edit,write - Execution:
bash,python_exec
Reads are bounded and parallel-capable. edit accepts only path plus exact, unique edits: [{ oldText, newText }]; every match resolves against the original file and the write is atomic. Use write to replace an entire file. Bash is finite/noninteractive and process-tree cancellable; use task_start for servers and watchers. Python accepts exactly one code/file source, has no stdin, and is capped at 600 seconds.
Web and Atlassian
Section titled “Web and Atlassian”- Web:
web_search,web_fetch - Jira reads:
jira_search_users,jira_search_issues,jira_get_issue,jira_get_project,jira_search_boards,jira_get_board,jira_get_sprint,jira_download_attachment - Jira writes:
jira_create_issue,jira_update_issue,jira_transition_issue,jira_manage_comment,jira_manage_worklog,jira_manage_issue_link,jira_manage_attachment,jira_manage_sprint,jira_manage_backlog - Confluence reads:
confluence_search_spaces,confluence_search_pages,confluence_get_page,confluence_download_page - Confluence writes:
confluence_create_page,confluence_update_page,confluence_manage_comment,confluence_manage_page,confluence_manage_label,confluence_manage_restriction,confluence_manage_attachment
Web search/fetch, image explanation, and Python are individual global tool toggles. Search requires Tavily. Jira/Confluence require enabled modules and credentials. Atlassian responses and mutation reports are always saved as managed raw artifacts while the agent receives a bounded semantic preview. Related Jira/Confluence data is selected with each read tool’s compact include array.
Image explanation
Section titled “Image explanation”explain_image
Choose an image-capable fallback model and its thinking level under Settings → Tools, then explicitly enable the tool. It is exposed only when the current agent model is text-only. When disabled, it is absent from the agent’s tool schema and system prompt.
The tool accepts an absolute or project-relative JPEG, PNG, GIF, or WebP path and an optional focus prompt. It sends the image to the configured vision model and returns only bounded explanatory text to the primary model. Cloud providers receive the image bytes; a compatible local provider can keep processing local.
Interaction and to-dos
Section titled “Interaction and to-dos”ask_usertodos_set,todos_get
Questions suspend a run. To-dos are structured current-work state, not background processes.
Background tasks
Section titled “Background tasks”task_start,task_status,task_logs,task_control
Task start accepts a project-relative cwd, an optional discriminated ready object (url, detected_url, or pattern), encrypted-at-rest env values, and runtime up to 24 hours. Its result also reports other active tasks in the project scope. task_status selects IDs/names with tasks; task_logs selects one task and uses one mode-specific cursor; task_control selects one task for stop or restart. Logs are bounded and agents receive asynchronous updates rather than polling.
Explore and planning
Section titled “Explore and planning”exploreplan_mode_enter,plan_mode_present,plan_mode_force_exit
Explore accepts 1–8 child tasks, with 8 active and 24 total launches per parent run. Children are isolated/read-only and receive only read, grep, find, ls, task_status, and task_logs.
Not agent tools
Section titled “Not agent tools”Workbench Git/GitHub routes and Agent Browser skill discovery are not tool names. Agents use Git through Bash; Agent Browser contributes optional prompt guidance.
Risks include read, workspace write, command, network, secret, destructive, agent spawn, deployment, and interaction. Read tools and policy before treating a risk label as a security boundary.